Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRIVACY: Do not store IP address more than 4 years #228

Open
3 tasks
tiblu opened this issue Jan 31, 2022 · 3 comments
Open
3 tasks

PRIVACY: Do not store IP address more than 4 years #228

tiblu opened this issue Jan 31, 2022 · 3 comments
Labels
bug Existing feature not working as designed.

Comments

@tiblu
Copy link
Member

tiblu commented Jan 31, 2022

What is the problem?

Privacy policy states that we keep User IP for 3 months. It will be updated to be 4 years to be compliant with GDPR

The reality is that Citizen OS has User IP stored for more than 4 years as we don't have any automation to remove them:

  • In Activities table inside actor object.
  • In database backups older than 4 years.

Why is this a problem?

It goes against Citizen OS privacy policy - https://citizenos.com/legal/privacy/

Possible solution.

  • Put in place a mechanism that will continuously mask/obfuscate/remove IP address in the actor object in the Activities table for activities older than 4 years. We MAY want to use obfuscation to connect different activites from same IP while NOT actually connecting to a person.
  • Put in place a mechanism that will continuously remove all DB backups older than 4 years.
  • Any other places?

Related issues

@tiblu tiblu added the bug Existing feature not working as designed. label Jan 31, 2022
@ilmartyrk ilmartyrk changed the title PRIVACY: Do not store IP address more than 3 months PRIVACY: Do not store IP address more than 4 years Jan 31, 2022
@ilmartyrk
Copy link
Member

@tiblu, we should actually store IP for 4 years #102 (comment)
I have changed the issue and replaced your initial texts from 3-months to 4 years. We will get our PP updated by @KatiVellak

@anettlinno
Copy link
Collaborator

Triage 60. Important update. We need to automate removing IPs after 4 years of storage. Est. dev time 8 hours. Sending to development.

@BeccaMelhuish
Copy link
Contributor

@ssin1901 @ilmartyrk Will put this to 'soon' as it seems important if not already fixed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Existing feature not working as designed.
Projects
Development

No branches or pull requests

4 participants